<Past |
Future> |
12.5 |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [3] |
Approved w/Constraints [3] |
Approved w/Constraints [3] |
Approved w/Constraints [3] |
Approved w/Constraints [4, 5, 6, 7] |
Divest [4, 5, 6, 7] |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
12.5.4 |
Approved w/Constraints [2] |
Approved w/Constraints [2] |
Approved w/Constraints [3] |
Approved w/Constraints [3] |
Approved w/Constraints [3] |
Approved w/Constraints [3] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [5, 6, 7, 8] |
Approved w/Constraints [5, 6, 7, 8] |
12.6.7 |
Unapproved |
Unapproved |
Approved w/Constraints [1, 3] |
Approved w/Constraints [1, 3] |
Approved w/Constraints [1, 3] |
Approved w/Constraints [1, 3] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Divest [5, 6, 7, 8] |
Divest [5, 6, 7, 8] |
12.6.8 |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [4, 5, 6, 7] |
Approved w/Constraints [5, 6, 7, 8] |
Approved w/Constraints [5, 6, 7, 8] |
| | [1] | This Technology is currently being evaluated, reviewed, and tested in controlled environments. Use of this technology is strictly controlled and not available for use within the general population. | | [2] | There Symantec advisory issued on 4/9/2012 requires a new hotfix (http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120301_00). The advisory recommends the following: Symantec released the latest version of pcAnywhere: pcAnywhere 12.5 SP4 and pcAnywhere Solution 12.6.7 which included many performance enhancements, all of the previous released security updates and enhancements to the security model of pcAnywhere. Symantec recommends all pcAnywhere users move to the latest release of their respective product. TECH182142 provides the most current updated hot fix information to include all available patches that have been released for Symantec pcAnywhere. If users have have already applied previous hot fixes they will still need to apply the latest TECH182142 hot fix. If users have NOT applied previous Symantec pcAnywhere 12.5 SP3 hot fixes, then the TECH182142 hot fixes must be installed.
Additionall, since this application allows remote access to hosts, the application must be configured in accordance with the specific configurations as stated in the VA Firewall Configuration Requirements SOP.
The requirements are as follows: pcANYWHERE software installed on VA workstations and servers must be configured in accordance with the Baseline Security Configuration Guide for pcAnywhere developed by OCIS. For remote desktop control only FIPS 140-2 validated remote control products such as pPcAnywhere and MS RDP (Terminal Services) operated in FIPS 140 mode in conjunction with One-VA VPN (IPSec or SSL) with two-factor authentication and auditing can be used for VA IT systems. Reference OMB Memo M-06-16, NIST FIPS 140-2 and various VA Memos and Directives. | | [3] | The Symantec advisory issued on 4/9/2012 requires a new hotfix (http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120301_00).
The advisory recommends the following: Symantec released the latest version of pcAnywhere 12.5 SP4 and pcAnywhere Solution 12.6.7 which included many performance enhancements, and all of the previous released security updates and enhancements to the security model of pcAnywhere. Symantec recommends all pcAnywhere users move to the latest release of their respective product.
TECH182142 provides the most current updated hot fix information to include all available patches that have been released for Symantec pcAnywhere. If users have already applied previous hot fixes, they will still need to apply the latest TECH182142 hot fix. If users have NOT applied previous Symantec pcAnywhere 12.5 SP3 hot fixes, then the TECH182142 hot fixes must be installed. Additionally, since this application allows remote access to hosts, the application must be configured in accordance with the specific configurations as stated in the VA Firewall Configuration Requirements SOP.
The requirements are as follows: pcAnywhere software installed on VA workstations and servers must be configured in accordance with the Baseline Security Configuration Guide for pcAnywhere developed by OCIS. For remote desktop control, only FIPS 140-2 validated remote control products such as pcAnywhere and MS RDP (Terminal Services) operated in FIPS 140 mode in conjunction with One-VA VPN (IPSec or SSL) with two-factor authentication and auditing can be used for VA IT systems. Reference OMB Memo M-06-16, NIST FIPS 140-2 and various VA Memos and Directives.
| | [4] | Additional requirements are as follows: pcAnywhere software installed on VA workstations and servers must be configured in accordance with the Baseline Security Configuration Guide for pcAnywhere developed by OCIS (See Reference Section for more information). For remote desktop control only FIPS 140-2 validated remote control products such as pcAnywhere and MS RDP (Terminal Services) operated in FIPS 140 mode in conjunction with One-VA VPN (IPSec or SSL) with two-factor authentication and auditing can be used for VA IT systems. Reference OMB Memo M-06-16, NIST FIPS 140-2 and various VA Memos and Directives. | | [5] | Due to National Institute of Standards and Technology (NIST) identified security vulnerabilities, extra vigilance should be applied to ensure the versions remain properly patched to mitigate known and future vulnerabilities. The local ISO can provide assistance in reviewing the NIST vulnerabilities. | | [6] | Veterans Affairs (VA) users must ensure VA sensitive data is properly protected in compliance with all VA regulations. All instances of deployment using this technology should be reviewed by the local ISO (Information Security Officer) to ensure compliance with VA Handbook 6500. | | [7] | In cases where the technology is used for external connections, a full Enterprise Security Change Control Board (ESCCB) review is required in accordance VA Directive 6004 , VA Directive 6517, and VA Directive 6513. The local ISO can advise on the ESCCB review process. | | [8] | pcAnywhere software installed on VA workstations and servers must be configured in accordance with the Baseline Security Configuration Guide for pcAnywhere developed by Office of Cyber and Information Security (OCIS) (See Reference Section for more information). For remote desktop control only Federal Information Processing Standards (FIPS) 140-2 validated remote control products such as pcAnywhere and Microsoft Remote Display Protocol (MS RDP) (Terminal Services) operated in FIPS 140 mode in conjunction with One-VA Virtual Private Network (VPN) [Internet Protocol Security (IPsec) or Secure Sockets Layer (SSL)] with two-factor authentication and auditing can be used for VA Information Technology (IT) systems. Reference Office of Management & Budget (OMB) Memo M-06-16, NIST FIPS 140-2 and various VA Memos and Directives. |
|